Sigma Rule Library

User Added To Admin Group Via Dscl

Detects attempts to create and add an account to the admin group via "dscl"

View on GitHubOpen raw file

Detection logic

selection

Image|endswith: /dscl
CommandLine|contains|all:
  - " -append "
  - " /Groups/admin "
  - " GroupMembership "

Condition

selection

Raw YAML

title: User Added To Admin Group Via Dscl
id: b743623c-2776-40e0-87b1-682b975d0ca5
related:
    - id: 0c1ffcf9-efa9-436e-ab68-23a9496ebf5b
      type: obsolete
status: test
description: Detects attempts to create and add an account to the admin group via "dscl"
references:
    - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1078.003/T1078.003.md#atomic-test-2---create-local-account-with-admin-privileges---macos
    - https://ss64.com/osx/dscl.html
author: Sohan G (D4rkCiph3r)
date: 2023-03-19
tags:
    - attack.persistence
    - attack.initial-access
    - attack.privilege-escalation
    - attack.stealth
    - attack.t1078.003
logsource:
    category: process_creation
    product: macos
detection:
    selection: # adds to admin group
        Image|endswith: '/dscl'
        CommandLine|contains|all:
            - ' -append '
            - ' /Groups/admin '
            - ' GroupMembership '
    condition: selection
falsepositives:
    - Legitimate administration activities
level: medium

False positives

  • Legitimate administration activities

References

  • obsolete0c1ffcf9-efa9-436e-ab68-23a9496ebf5b

Similar rules